Unauthorized File Access in npm CLI before before version 6.13.3
Published Dec 13, 2019
8.1
HIGHCVSS 3.1
EPSS 3.42%
Description
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Affected products
-
- Version < 6.13.3StatusaffectedConstraints<6.13.3
- Version
Configuration 4
- 31
Configuration 5
- 8.0
- 8.1
No data.
Red Hat Enterprise Linux 8
nodejs:10-8010020200213140254.c27ad7f8
Fixed · RHSA-2020:0579
Red Hat Enterprise Linux 8
nodejs:12-8010020200116150415.c27ad7f8
Fixed · RHEA-2020:0330
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
nodejs:10-8000020200214110450.f8e95b4e
Fixed · RHSA-2020:0573
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs8-nodejs-0:8.17.0-2.el7
Fixed · RHSA-2020:2625
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs8-nodejs-0:8.17.0-2.el7
Fixed · RHSA-2020:2625
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.19.0-1.el7
Fixed · RHSA-2020:0597
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.16.1-1.el7
Fixed · RHSA-2020:0602
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs8-nodejs-0:8.17.0-2.el7
Fixed · RHSA-2020:2625
Red Hat OpenShift Application Runtimes
nodejs8
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs:10-8010020200213140254.c27ad7f8 | Fixed | RHSA-2020:0579 |
| Red Hat Enterprise Linux 8 | nodejs:12-8010020200116150415.c27ad7f8 | Fixed | RHEA-2020:0330 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs:10-8000020200214110450.f8e95b4e | Fixed | RHSA-2020:0573 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs8-nodejs-0:8.17.0-2.el7 | Fixed | RHSA-2020:2625 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs8-nodejs-0:8.17.0-2.el7 | Fixed | RHSA-2020:2625 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.19.0-1.el7 | Fixed | RHSA-2020:0597 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.16.1-1.el7 | Fixed | RHSA-2020:0602 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs8-nodejs-0:8.17.0-2.el7 | Fixed | RHSA-2020:2625 |
| Red Hat OpenShift Application Runtimes | nodejs8 | Out of support scope | n/a |
npm
npm
Introduced 0 Fixed 6.13.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | npm | 0 | 6.13.3 |
Remediation
No remediation recorded yet.
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00027.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHEA-2020:0330 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0573 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0579 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0597 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0602 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-16776 Vendor Advisory
- https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli x_refsource_MISCThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1788310 Issue Tracking
- https://github.com/advisories/GHSA-x8qc-rrcw-4r46 Advisory
- https://github.com/npm/cli/security/advisories/GHSA-x8qc-rrcw-4r46 x_refsource_CONFIRMThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/
- https://nvd.nist.gov/vuln/detail/CVE-2019-16776
- https://www.cve.org/CVERecord?id=CVE-2019-16776
- https://www.npmjs.com/advisories/1436
- https://www.oracle.com/security-alerts/cpujan2020.html x_refsource_MISCThird Party Advisory
Change history (0)
No recorded changes yet.